CVE-2011-4514
The TELNET daemon in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced;...
Affects 5 products across 1 vendor.
Software does not prove or insufficiently proves that the user is who they claim to be.
Show all 10
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
The TELNET daemon in multiple Siemens WinCC products and SIMATIC HMI panels does not perform authentication, allowing remote attackers to gain unauthorized access via a TCP session. This vulnerability has a CVSS score of 10.0, indicating critical severity.
BSID: BS-2012-GLOBAL-089483-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2011-4514?
What is the CVSS score for CVE-2011-4514?
Is CVE-2011-4514 actively exploited?
How do I remediate CVE-2011-4514?
What systems are affected by CVE-2011-4514?
What NERC-CIP standard applies to CVE-2011-4514?
What IEC 62443 requirement maps to CVE-2011-4514?
| CVE ID | CVE-2011-4514 |
|---|---|
| BSID | BS-2012-GLOBAL-089483-C BreachSpider Global ID |
| CVSS Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| Published | 2012-02-03 |
| Last Modified | 2026-04-29 |
| ICS Relevance | 80% |
| Weakness (CWE) | |
| Verticals | |
| Source | NVD |
The TELNET daemon in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime does not perform authentication, which makes it easier for remote attackers to obtain access via a TCP session.
Source: NIST NVD / MITRE CVE Database
Remote attackers can exploit this vulnerability by establishing a TCP connection to the TELNET service on the affected devices. Since no authentication is required, the attacker can gain full control over the device, leading to potential data exfiltration, command execution, and system compromise.
Exploitation Likelihood: MEDIUM
| Vendor | Product | Fixed Version |
|---|---|---|
| Siemens | Wincc Flexible | — |
| Siemens | Wincc | — |
| Siemens | Simatic Hmi Panels | — |
| Siemens | Wincc Runtime Advanced | — |
| Siemens | Wincc Flexible Runtime | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Implement network segmentation to isolate the affected systems from untrusted networks. Use firewalls to restrict access to the TELNET service only to trusted IP addresses.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.
This CVE violates CIP-007-R2 because it allows unauthorized access to the TELNET service without proper authentication, which could lead to the compromise of critical assets.
This CVE maps to SR 7.6 because it involves a lack of authentication for a network service, which is a fundamental security requirement to prevent unauthorized access and control of industrial systems.
Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.
SAGE Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 4378b98e7e3afcb7ce0a00f708397e17bd837a3dbc2549d6a1680869876c814883068af226872afbdc009171d63c6b002c32ffec7254e63296b574689b35a93c |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →